IQON Phase 1 Hardening Package
Purpose: локальный пакет временного hardening для live WordPress iqon.com до полноценного редизайна или статической замены.
Contents
- Scope
- Files
- Install Draft
- Hosting Rule Draft
- Automated Verification Script
- Verification
- Rollback
- Limits
Scope
Пакет не был установлен на live-сайт. Он подготовлен как reversible snippet для Code Snippets и должен применяться только после отдельного подтверждения на запись во внешний WordPress.
Files
| File | Role |
|---|---|
wp-snippets/iqon-phase1-hardening.php |
PHP snippet for Code Snippets, "Run snippet everywhere" |
wp-snippets/hosting-rules.md |
nginx/Apache/file-level drafts for install docs and XML-RPC |
scripts/iqon-phase1-verify.sh |
Post-activation verification script |
Install Draft
- Открыть WordPress admin через текущий безопасный маршрут доступа.
- Создать новый snippet с названием
IQON Phase 1 hardening. - Вставить содержимое
wp-snippets/iqon-phase1-hardening.php. - Выбрать режим
Run snippet everywhere. - Сохранить snippet как inactive draft.
- Сделать свежий backup файлов и базы перед активацией.
- Активировать snippet.
- Сразу выполнить проверки из раздела Verification.
Hosting Rule Draft
PHP snippet не гарантирует блокировку физических файлов, которые веб-сервер отдаёт до WordPress. Для readme.html и license.html нужен server-level блок или удаление файлов.
nginx draft:
location ~* ^/(readme|license)\.html$ {
return 404;
}
Если на reg.ru shared hosting нет доступа к nginx-конфигу, проверить доступные механизмы: панель хостинга, .htaccess, файловый менеджер или удаление публичных install-doc файлов после backup.
Detailed drafts are in wp-snippets/hosting-rules.md.
Automated Verification Script
After activation:
scripts/iqon-phase1-verify.sh https://iqon.com
Expected signal: final line is [OK] iqon Phase 1 verification passed for https://iqon.com.
Verification
Run after activation:
curl -I -L https://iqon.com/
Expected signal: response includes X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and Content-Security-Policy.
curl -sS https://iqon.com/wp-json/wp/v2/users
Expected signal: no public list of usernames is returned.
curl -sS https://iqon.com/ | rg 'http://www\.iqon\.com|http://iqon\.com|http://maps\.google\.com'
Expected signal: no output.
curl -sS https://iqon.com/ | rg 'name="viewport"|iqon-skip-link|og:site_name'
Expected signal: viewport exists, skip link exists, site metadata no longer shows - IQON.
curl -I -L https://iqon.com/readme.html
Expected signal after hosting rule: 403 or 404. If it still returns 200, WordPress snippet is bypassed by static file serving and hosting-level action is still required.
curl -I --http1.1 https://iqon.com/xmlrpc.php
Expected signal: no usable XML-RPC behavior. A stronger check is a safe XML-RPC POST from a test client after confirming no production integrations depend on it.
Rollback
- Disable the
IQON Phase 1 hardeningsnippet. - Clear any page/cache layer if present.
- Re-run the same curl checks and compare before/after.
- Remove hosting rule only if it caused a confirmed false positive.
Limits
- This package does not replace the contact form or legacy CAPTCHA.
- This package does not fix duplicate sitemap URLs.
- This package does not modernize the WordPress theme.
- This package does not verify canonical contact data.
- This package does not confirm the exact WordPress core version.
Created: 20 May 2026 Updated: 20 May 2026